dev-testing-frontend

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • External Downloads & Remote Code Execution: The skill utilizes npx to fetch and execute documentation and analysis tools from the @sveltejs organization. This is a common method for utilizing modern development utilities from established software maintainers.
  • Command Execution: The instructions involve standard shell commands for development workflows, including pnpm, vitest, and just. These operations are expected within the scope of a software testing and build pipeline.
  • Indirect Prompt Injection Surface: The svelte-autofixer tool processes external code strings or file paths as input, which creates a surface for potential indirect prompt injection. This risk is inherent to the tool's intended purpose of analyzing and suggesting fixes for code. (1) Ingestion points: The <code_or_path> argument in the svelte-autofixer CLI command within references/svelte5.md accepts external content. (2) Boundary markers: The instructions recommend escaping shell-sensitive characters like $, but do not specify internal prompt delimiters for the model. (3) Capability inventory: The skill has the capability to execute shell commands for testing, building, and documentation retrieval. (4) Sanitization: Manual escaping of characters is recommended in the guidelines to prevent unintended shell substitution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:45 PM
Security Audit — agent-trust-hub — dev-testing-frontend